ZeroHour

CVE-2024-50599

large

Reflected XSS in Zimbra Collaboration Suite 8.8.15 webmail calendar endpoint

CVSS 3.1
6.1 medium
EPSS
61%p99
Published
()
Modified
AI analysis

CVE-2024-50599 is a reflected Cross-Site Scripting (XSS) flaw (CWE-79) in one of the webmail calendar endpoints of Zimbra Collaboration Suite (ZCS) 8.8.15, caused by improper handling of user-supplied input that is reflected back into the HTML response. An attacker triggers it by getting a victim to click a crafted link to the calendar endpoint; the injected code is then reflected and executed in the victim's browser. Successful exploitation lets the attacker run script in the victim's webmail session context, with potential to steal session information or act as the user (CVSS 6.1 medium, user interaction required, scope changed). Organizations running ZCS 8.8.15, particularly those exposing webmail to the internet, are affected. The flaw is not yet in the CISA KEV catalog and no public proof-of-concept is known, but the 60.7% EPSS score (99th percentile) indicates a high probability of exploitation within 30 days.

What to do: Apply the latest 8.8.15 patch level published by Synacor in its security advisory, or migrate to a currently supported ZCS release, without delay given the elevated EPSS score. Restrict internet exposure of the webmail calendar endpoint where possible and review webmail access logs for anomalous requests to calendar URLs. Caution users against clicking untrusted links that point to their webmail domain, since reflected XSS requires user interaction.

Affected
Synacor Zimbra Collaboration Suite (ZCS)8.8.15 (only version named in the advisory; webmail calendar endpoint)
Estimated exposure
largetens of thousands of internet-exposed Zimbra servers (roughly 30k-40k per public internet scans), with the 8.8.15 share unverified — Public internet-wide scans such as Shodan and Censys have historically indexed on the order of 30,000-40,000 exposed Zimbra instances, and 8.8.15 has been one of the most widely deployed branches, making this at least a 10k-100k-system…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Zimbra Collaboration Suite (ZCS) 8.8.15, affecting one of the webmail calendar endpoints. This arises from improper handling of user-supplied input, allowing an attacker to inject malicious code that is reflected back in the HTML response.

Vendors
synacor
Products
zimbra collaboration suite
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.